Quantum Audit Logo

Is Basehat Safe?

On-chain security analysis — is it a scam or legit?

Basehat BASEHAT
0xb200…4a01
Base Not verifiedLast checked 2d ago 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

This audit report is based on the provided contract address without access to its source code. Therefore, a comprehensive security analysis could not be performed. The findings below highlight general security considerations that would typically be assessed, but their applicability and resolution status remain unverified.

3 Informational
Volume 24h
$51.4K
Liquidity
$42.4K
Price
$0.0001043
Token Age
14d
Top 10 Holders
29.8%

Security Findings

Info

Source Code Unavailable for Technical Analysis

I-01The contract source code for address 0xb200…4a01 was not provided. This prevents a detailed technical security assessment, including checks for common vulnerabilities like reentrancy, integer overflows/underflows, denial-of-service, and logic errors (7.2 Code Security).
IssueThe contract source code for address was not provided. This prevents a detailed technical security assessment, including checks for common vulnerabilities like reentrancy, integer overflows/underflows, denial-of-service, and logic errors (7.2 Code Security).
FixAlways provide verified source code for any smart contract intended for public deployment or audit. This enables a comprehensive review of the contract's logic and security posture.
StatusUnresolved
Info

Access Control and Privileged Functions Unverified

I-02Without the contract's source code, it is impossible to verify the implementation of access control mechanisms (7.3 Access Control) and identify any privileged functions. This includes assessing whether critical operations are adequately protected, if ownership is properly managed, or if there are potential single points of failure.
IssueWithout the contract's source code, it is impossible to verify the implementation of access control mechanisms (7.3 Access Control) and identify any privileged functions. This includes assessing whether critical operations are adequately protected, if ownership is properly managed, or if there are potential single points of failure.
FixImplement robust access control using established patterns (e.g., OpenZeppelin's Ownable or AccessControl). Clearly define and document all privileged roles and their associated permissions. Ensure multi-signature wallets are used for critical administrative actions.
StatusUnresolved
Info

Economic, Governance, and Upgradeability Risks Unassessed

I-03The absence of source code and project context prevents any assessment of economic (7.4), governance (7.5), external (7.6), and upgradeability (7.7) risks. This includes potential for oracle manipulation, flash loan attacks, governance centralization, or unsafe upgrade paths. Operational aspects (7.8) also remain unverified.
IssueThe absence of source code and project context prevents any assessment of economic (7.4), governance (7.5), external (7.6), and upgradeability (7.7) risks. This includes potential for oracle manipulation, flash loan attacks, governance centralization, or unsafe upgrade paths. Operational aspects (7.8) also remain unverified.
FixProvide comprehensive documentation detailing the protocol's economic model, governance structure, external dependencies, and upgrade strategy. For upgradeable contracts, ensure a secure proxy pattern is used and thoroughly tested.
StatusUnresolved

Category Ratings

TechnicalLow8/10

Due to the absence of contract source code, a comprehensive technical security analysis (7.1 Architecture, 7.2 Code Security, 7.3 Access Control) could not be performed. Therefore, specific vulnerabilities such as reentrancy, integer overflows, or improper access control mechanisms cannot be identified or confirmed. General best practices for secure smart contract development are assumed but unverified.

GovernanceHigh2/10

Without access to the contract's source code and broader protocol documentation, an assessment of economic (7.4) and governance (7.5) risks is not possible. This includes analysis of tokenomics, incentive mechanisms, potential for oracle manipulation, or governance attack vectors. External dependencies (7.6) and their associated risks also remain unexamined.

UpgradesMedium6/10

The upgradeability architecture (7.7) of the contract could not be determined without source code. This prevents an analysis of potential upgrade safety issues, such as storage collisions in proxy patterns or improper initialization logic. Operational aspects (7.8) related to contract administration and emergency procedures also remain unverified.

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint Function?
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

5.0% in wallets24.8% in contracts
Effective Concentration14.9%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder53.4%
Top-3 Unlocked93.8%

Key Addresses

Unlocked LP Held By
0x1623…ab5b0x1983…a2580x3dd5…599d0x72b5…5a230x170f…7cec

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership status UNKNOWN (owner could not be resolved)
  • Mint capability UNKNOWN (implementation ABI unreadable)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • Liquidity < $50k ($42,644 across 6 pairs — thin market)
  • LP top1 unlocked holder = 53.4% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • LP top3 unlocked holders = 93.8% (independent LP — depth risk, pool = 99% of DEX liquidity)
  • Token age < 30 days (still settling)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

PlayMedium RiskThe Stonks Exchange (STONKEX)Medium RiskOpalMedium Riskaixbt by Virtuals (AIXBT)Medium RiskOpenGradient (OPG)Medium RiskZoraMedium Risk

Would You Like a More Detailed Audit of Basehat?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit